UCF STIG Viewer Logo

RSS Attachment Downloads


Overview

Finding ID Version Rule ID IA Controls Severity
V-15682 5.231 SV-29451r1_rule ECSC-1 Medium
Description
This check verifies that attachments are prevented from being downloaded from RSS feeds.
STIG Date
Windows 2008 Domain Controller Security Technical Implementation Guide 2014-04-02

Details

Check Text ( C-15326r1_chk )
Note: For Windows XP, this check only applies if Internet Explorer 7 or later is installed.

If the following registry value doesn’t exist or is not configured as specified this is a finding:

Registry Hive: HKEY_LOCAL_MACHINE
Subkey: \Software\Policies\Microsoft\Internet Explorer\Feeds\

Value Name: DisableEnclosureDownload

Type: REG_DWORD
Value: 1
Fix Text (F-15549r1_fix)
Note: For Windows XP, this only applies if Internet Explorer 7 or later is installed.

Configure the policy value for Computer Configuration -> Administrative Templates -> Windows Components -> RSS Feeds “Turn off downloading of enclosures” to “Enabled”.